The Karma ransomware group is known for RaaS-based double-extortion attacks targeting healthcare, manufacturing, and technology sectors.
Analyst brief
The Karma ransomware group has been active since mid-2021, originating from earlier variants like Nefilim and FiveHands, and was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains. The group primarily targets enterprises in the healthcare, manufacturing, and technology sectors, operating on both Windows and Linux platforms. It employs double-extortion tactics—encrypting and exfiltrating data—with TTPs centered on the RaaS model. Defenders should focus on ransomware threats using double-extortion, especially in healthcare, manufacturing, and technology sectors, by enhancing network monitoring and backup strategies to mitigate data exfiltration risks.
karma
crime
Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating double-extortion attacks against enterprises in healthcare, manufacturing, and technology; the group was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains.
Platforms: Windows and Linux